← All legal documents
Bug Bounty Program
Last updated: 5 juin 2026
Wajub encourages the security research community to help us maintain a high level of security for our platform and our users. Our bug bounty programme rewards researchers who discover and report security vulnerabilities in good faith via hackerone.com/wajub.
1. Scope
Included domains and services: *.wajub.com, *.wajub.app, api.wajub.com, dashboard.wajub.com, konsole.wajub.com, pay.wajub.com, help.wajub.com, status.wajub.com, docs.wajub.com, Wajub Dashboard mobile apps, the public REST API, official SDKs (JavaScript, Python, PHP, Go, Java, .NET), and UI components. Excluded: merchant sites, third-party providers (MTN MoMo, Stripe, etc.), underlying infrastructure (AWS), physical attacks, DoS/DDoS, and social engineering.
2. Eligible vulnerabilities
Rewarded vulnerabilities: XSS (stored, reflected, DOM-based), CSRF on sensitive actions, SSRF with demonstrated impact, injections (SQL, NoSQL, LDAP, OS command), IDOR, authentication bypass, privilege escalation, business logic flaws with impact, sensitive data exposure, subdomain takeover, race conditions, and mass assignment. Not eligible: self-XSS, missing HTTP security headers without impact, non-sensitive clickjacking, version disclosure, rate limiting without business impact, and automated reports without proof of concept.
3. Rewards
Indicative scale (USD): Critical — $2,000 to $5,000 (RCE, account takeover, infrastructure access, massive data leak). High — $1,000 to $2,000 (auth bypass, critical IDOR, SQL injection). Medium — $500 to $1,000 (stored XSS, sensitive CSRF, limited SSRF). Low — $100 to $500 (reflected XSS, minor information disclosure). Bonuses: first report +20%, report with fix +10%, report with test automation +10%.
4. Participation rules
Researchers undertake to act in good faith, not to exploit the vulnerability beyond demonstration, not to access or modify data that does not belong to them, not to disclose before remediation (default period of 90 days), and not to use brute force or DoS attacks. Wajub undertakes not to pursue legal action against researchers acting in good faith (safe harbour) and to handle reports professionally.
5. Reporting process
Reports must be submitted via hackerone.com/wajub. A good report contains: clear title, CWE/OWASP type, affected URL, detailed reproduction steps, proof of concept (PoC), potential impact, and environment. Processing times: acknowledgement < 24h, initial triage < 48h, validation < 5 days. Remediation: critical < 7 days, high < 14 days, medium < 30 days, low < 60 days. Reward after fix validation.
6. Programme exclusion
Wajub reserves the right to exclude a researcher in the event of non-compliance with the rules, premature public disclosure, attacks beyond the necessary scope, attempted extortion or blackmail, or harassment of teams. Wajub reserves the right to modify the programme terms at any time; changes are published on the HackerOne page.
Compliance questions: compliance@wajub.com